jlasman said:
If there were a separate closed forum where we'd announce security issues how would that stop anyone else from writing them up in other forum sections? It wouldn't.
Unless we closed the whole forum to all writing. And then all new posts would have to be moderated. No thanks.
What Jon is suggesting isn't viable; by the time I get to the posts they're sometimes days old, so moving them to private forum pages is a bit late.
Ok, lets go back for a moment to the idea that started this thread:
What would be the reason for wanting to close (part of) the forum?
I think the reason for this idea is based on the fear that hackers may learn of an exploit while there are still Admins out there that haven't patched their servers yet, or worse, don't even know about the problem!
BUT, I think it is unrealistic to assume that there is a way to prevent information from getting in the hands of hackers. I don't think that closing (part of) the forum is a solution to that problem.
As far as I can see, the best solution is to take the advantage of learning about an exploit early, away from the hackers by having a mechanism that will let all Admins know about the issue as soon as it is discovered, so they can plug the hole before hackers can exploit it.
This requires a way of communication that is:
1) Fast
2) All Admins should know about it
3) All Admins should have access to it
A mailing list would satisfy all three requirements, especially if subscribing to the list is done through a link in the admin section of the DA user-interface.